Fake Zoom, Real Thieves: North Korean Hackers from BlueNoroff Scan Your Crypto Wallets
Your microphone isn’t working? It might be a trap. The cybersecurity company JUMPSEC has just dissected the latest campaign from BlueNoroff, an offshoot of the infamous Lazarus Group in the service of Pyongyang. The agenda includes fake Zoom and Microsoft Teams meetings, hijacked Telegram accounts, and malware that inventories the wallets of its victims even before striking. Crypto professionals are the primary targets, on both Windows and macOS.
Key Points {#h-key-points}
- BlueNoroff, linked to the North Korean Lazarus Group, traps crypto professionals through fake Zoom and Microsoft Teams meetings sent from hijacked Telegram accounts.
- The phishing kit inventories the browser wallet extensions to prioritize the wealthiest targets before delivering the malware.
- The malware strikes Windows and macOS: credentials, Chrome keys, and Telegram sessions are exfiltrated via a Telegram bot, with compromises occurring in less than five minutes.
- According to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in 2025, with a cumulative haul exceeding $6.75 billion since 2017.
Five Minutes to Trap a Victim {#h-five-minutes-to-trap-a-victim}
It all starts with an innocuous message. The target receives an invitation via the compromised Telegram account of a real contact or through a Calendly appointment link. The appointment leads to a typosquatted domain, meaning an address almost identical to that of the legitimate platform. More than 80 domains imitating Zoom or Teams have been registered since late 2025, according to researchers.
The fake meeting room takes realism to great lengths. Operators display fake participants, sometimes generated by AI or recycled from images of previous victims. From a control panel, the hacker animates the scene live and sends the infamous message: your microphone isn’t working.
The proposed solution? Install a supposed update for the Zoom SDK (Software Development Kit). This pretext actually triggers a ClickFix-type attack: the page copies a malicious command into the clipboard, and the victim executes it themselves in their terminal. In several documented cases, complete machine compromise took less than five minutes.
A Malware That Sorts Its Targets by Wallet {#h-a-malware-that-sorts-its-targets-by-wallet}
The real novelty lies in the reconnaissance phase. While the victim is busy fixing their fake microphone problem, the phishing kit scans their browser and lists the installed wallet extensions, with MetaMask at the top. Operators can thus gauge the value of each target and reserve their most elaborate payloads for the most well-stocked accounts.
Next comes the infection, tailored to the victim's system. On Windows, the execution chain installs persistence, remote control, and credential theft. On macOS, a fake Zoom or Teams installer appears while a stealer in the background sucks up system information, the master keys of Chrome stored in Apple’s Keychain, and Telegram sessions. The data then flows to a Telegram bot, and the malware can download an additional payload. JUMPSEC identified four macOS variants between April 22 and July 15, evidence of continuously refined tooling throughout the campaign.
< Malicious actors increasingly recognize that compromising individuals who control access can be as valuable as attacking the infrastructure itself. >
Researchers from JUMPSEC, in their report
Pyongyang and Its Crypto Heist Industry {#h-pyongyang-and-its-crypto-heist-industry}
BlueNoroff does not operate alone. The group belongs to the Lazarus galaxy, this digital armed wing of the North Korean regime that has already created fake companies to trap developers and is heavily suspected in the Upbit hack. The numerical tally is staggering: according to Chainalysis, North Korea stole a record approximately $2 billion in cryptocurrencies in the year 2025 alone, including the Bybit heist of $1.5 billion. Since 2017, Pyongyang's cumulative haul exceeds $6.75 billion, enough to sustainably fund its armament programs.
In the face of adversaries of this caliber, a few simple reflexes remain the best defenses. Always check the exact domain of a meeting link, even if sent by a close contact, as their Telegram account may have been hijacked. Never paste a command into your terminal at the request of a website; no legitimate video conference requires it. And keep the majority of your funds on a hardware wallet isolated from your work machine: the day the fake Zoom rings, it will find nothing to scan.
Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.
You may also like

Bitcoin Reduces Its Difficulty for the Ninth Time in 2026

Metaplanet plans Bitcoin-backed bonds yielding up to 6%

The Maid

NY Attorney General Letitia James warns Clarity Act would 'dilute' states' ability to go after fraud as pressure mounts

Argentina's Video Analyst Discusses the 2026 World Cup Final: "Spain Was Far Superior"

Messi Effect: Inter Miami Continues to Boost Its Earnings After the World Cup

PlayStation: Decision to Abandon Physical Support Threatens a $7.2 Billion Business

Microsoft Says MDASH Beats Claude Mythos and GPT-5.6 Sol in Cybersecurity Test

Trump's Second Term: 18 Months In... AI and Stock Market Steady, but 'K-Shaped Stagnation' Deepens

Bidding Opens for ARSA: Who Are the Interested Parties and How Much Are They Offering for the Former SanCor Yogurt Producer?

World Enters 'Phase 3,' Extends Proof of Human to AI Agents

Mbappé's Open Letter to France After His Team's Disappointment in the 2026 World Cup

Prime Video Unveils First Trailer for 'Carrie', Its New Series Based on Stephen King's Novel

Is the fixed term still yielding? How much do $3,000,000 generate in 30 days

Without Infrastructure, There Is No Mining or Energy: Canada's Plan to Accelerate Investments

Vaca Muerta Looks to the Pacific: The Neuquén-Chile Corridor Gains Importance for Exporting Energy to the World

Security Warning for Cloud Users; Shared Chats on Claude Indexed by Google

CFTC seeks urgent ruling on Minnesota prediction market ban

+500% in 24 Hours: A Look Back at the Largest Chinese IPO Since 2010

From Hot Storage to Cold Memory: Decentralized Storage in the AI Era

Progresar Scholarships: How to Claim the Additional $35,000 and the Key Requirement from ANSES

Between the Fed and inflation, Bitcoin enters a turbulent week

Tesla wins UK 5G patent appeal over $32 fee

Aníbal Fernández reappears in La Plata, calls to "protect Axel Kicillof" and distances himself from Kirchnerism

Bitcoin Becomes Increasingly Stable as Volatility Drops to Lowest Level in Years

End of the Line for BitMart: Trading Stops on August 26, Permanent Closure in January 2027

Everything You Need to Check on Your Car Before Doing the VTV to Pass the Process

Wheat and soybean prices reach two-year highs due to the impact of the Middle East war

Can Recent Crypto Exchange Closures Signal the End of the Bear Market?








